Pages
(Move to ...)
Blog
Code Snippets
▼
Monday, August 1, 2011
Windows Link Files / Using While Loops
›
A colleague asked today about a tool to decode Microsoft Windows link files. Before I begin to discuss the tool I recommended, I'll bri...
Tuesday, July 26, 2011
BlackBerry Messenger / Google Talk for BlackBerry Save-files
›
My last post, " BlackBerry Text Message Parsing, AKA, Why I use Linux for Forensics ," had unintended but pleasant consequences: i...
1 comment:
Thursday, July 21, 2011
BlackBerry Text Message Parsing, AKA, Why I use Linux for Forensics
›
A little detour from my usual posts to explain why I use Linux for forensics, though my upbringing was in Windows-based tools like EnCase. ...
3 comments:
Tuesday, July 19, 2011
Mounting Split Raw Images
›
A raw image, made with dd or a variant, is still a common image format, and will not go away soon even as many argue the benefits of forensi...
Wednesday, June 29, 2011
Google Chrome Download History
›
Google Chrome keeps a wealth of data that is of interest to the forensic examiner. There are tools that look at the browser history and cac...
Monday, June 13, 2011
Extending gThumb for forensics
›
I've searched high and low, and many times, for a good image viewer to be used in Linux-based forensics. In the end, and despite some s...
5 comments:
SD Card Construction, (or Burning Ants with a Magnifying Glass)
›
A coworker brought me an SD card today because she could not delete any files from it. I noticed the lock switch was missing from the card,...
‹
›
Home
View web version